# What Is the Default Logto Configuration?

> Discover the default Logto configuration including session TTL, refresh-token rotation, admin console flags, and ID token claims for secure and efficient user authentication.

- Repository: [Logto/logto](https://github.com/logto-io/logto)
- Tags: getting-started
- Published: 2026-07-02

---

**Logto initializes every new tenant with built-in OIDC defaults including a 14-day session TTL, conditional refresh-token rotation for public clients, and immutable admin console flags alongside predefined ID token extended claims.**

When you deploy the `logto-io/logto` platform, every new tenant receives a **default Logto configuration** that governs authentication behavior, administrative settings, and token claims. These values are hard-coded in the TypeScript source and seeded into the database during tenant creation, providing secure, production-ready defaults while remaining customizable through the Admin Console or Management API.

## OIDC Provider Defaults

Located in [`packages/core/src/oidc/defaults.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/oidc/defaults.ts), the OIDC defaults define core authentication behavior for the underlying OpenID Provider.

### Session and Refresh Token Policies

The default configuration implements specific **session TTL** and **refresh token rotation** logic:

- **sessionTtl**: Set to **14 days** (1209600 seconds), controlling how long a user session remains valid.
- **rotateRefreshToken**: Rotates public-client refresh tokens unless they are older than one year or already close to expiration.
- **refreshTokenTtl**: Uses custom TTL logic that respects rotated refresh tokens rather than a fixed duration.

## Admin Console and ID Token Defaults

Seed data defined in [`packages/schemas/src/seeds/logto-config.ts`](https://github.com/logto-io/logto/blob/main/packages/schemas/src/seeds/logto-config.ts) establishes the initial state for administrative settings and token claims.

### Immutable Admin Console Flags

Two boolean flags are frozen (cannot be mutated at runtime):

- **signInExperienceCustomized**: `false`
- **organizationCreated**: `false`

These flags track whether the tenant has customized its sign-in experience or created its first organization, serving as guardrails until configuration is completed through the UI.

### Default ID Token Extended Claims

Out of the box, Logto enables three extended claims in ID tokens:

```json
{
  "enabledExtendedClaims": ["roles", "organizations", "organization_roles"]
}

```

This configuration allows applications to immediately access user roles and organizational membership data without additional API calls.

## Accessing Defaults Programmatically

You can inspect these defaults using the Logto config library at [`packages/core/src/libraries/logto-config.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/libraries/logto-config.ts).

To access the **OIDC defaults** directly:

```ts
import defaults from '#src/oidc/defaults';

// Example: use the default session TTL for a new session cookie
const cookieMaxAge = defaults.sessionTtl; // 1209600 seconds (14 days)

```

To retrieve the **admin console configuration** via the library:

```ts
import { createLogtoConfigLibrary } from '#src/libraries/logto-config';

const configLib = createLogtoConfigLibrary({ /* …queries & pool… */ });
const adminConfig = await configLib.getJwtCustomizers(consoleLog);
// adminConfig includes the default frozen flags

```

To inspect the **ID token extended claims**:

```ts
import { createLogtoConfigLibrary } from '#src/libraries/logto-config';

const lib = createLogtoConfigLibrary({ /* … */ });
const idTokenConfig = await lib.getJwtCustomizers(consoleLog);
console.log(idTokenConfig.enabledExtendedClaims);
// → ['roles', 'organizations', 'organization_roles']

```

## Summary

- The **default Logto configuration** sets a **14-day session TTL** and intelligent refresh-token rotation for public clients via [`packages/core/src/oidc/defaults.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/oidc/defaults.ts).
- **Admin console flags** (`signInExperienceCustomized` and `organizationCreated`) start as `false` and are frozen to prevent runtime mutation.
- **ID tokens** ship with extended claims for `roles`, `organizations`, and `organization_roles` enabled by default.
- Access these values programmatically through the `createLogtoConfigLibrary` factory and direct imports from the OIDC defaults module.

## Frequently Asked Questions

### What is the default session TTL in Logto?

The default session TTL is **14 days** (1209600 seconds). This value is defined in [`packages/core/src/oidc/defaults.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/oidc/defaults.ts) and applies to all new tenants until overridden via environment variables or the Management API.

### Can I modify the default admin console flags programmatically?

No. The `signInExperienceCustomized` and `organizationCreated` flags are **frozen** in the database seed at [`packages/schemas/src/seeds/logto-config.ts`](https://github.com/logto-io/logto/blob/main/packages/schemas/src/seeds/logto-config.ts). They can only transition from `false` to `true` through specific user actions in the Admin Console or via sanctioned Management API endpoints, not by direct mutation.

### Which extended claims are enabled in ID tokens by default?

By default, Logto enables three extended claims: **roles**, **organizations**, and **organization_roles**. These are seeded in [`packages/schemas/src/seeds/logto-config.ts`](https://github.com/logto-io/logto/blob/main/packages/schemas/src/seeds/logto-config.ts) and allow applications to receive user authorization context immediately upon authentication.

### Where does Logto store its default OIDC configuration?

The OIDC defaults reside in [`packages/core/src/oidc/defaults.ts`](https://github.com/logto-io/logto/blob/main/packages/core/src/oidc/defaults.ts). This file exports the session TTL, refresh token rotation policies, and TTL calculation logic used by the underlying OIDC Provider.